lazarusholic

Everyday is lazarus.dayβ

Understanding the Ronin Network Exploit

2023-06-13, NeptuneMutual
https://neptunemutual.com/blog/understanding-the-ronin-network-exploit/
#AxieInfinity

Contents

Learn how the Ronin Network was exploited, resulting in a loss of approx. $624 million.

TL;DR
On March 23, 2022, the Ronin Network was exploited as a result of a private key compromise, which resulted in a loss of 173,600 ETH and 25.5 million USDC, totaling approximately $624 million.

Introduction to Ronin Network
Ronin is an EVM blockchain crafted for developers building games with player-owned economies.

Vulnerability Assessment
The root cause of the vulnerability is due to the compromise of the private key, which was effectively exploited by the hackers to forge fake withdrawals in order to steal the funds out of the Ronin Bridge.

Attack Scenario
Ronin was launched to offer the quick and affordable transaction throughput required for a P2E game to function. In order to maximize transactions per second, a Proof of Authority model was adopted, where nine validators staked their reputation rather than processing any power or funds.
Out of the nine validators, four were …